CVE-2026-46771: Medium severity Oracle Oracle Application Development Framework vulnerability
Vulnerability in the Oracle Application Development Framework (ADF) product of Oracle Fusion Middleware (component: Java Business Objects). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Difficult to exploit vulnerability allows high privileged attacker with logon to the infrastructure where Oracle Application Development Framework (ADF) executes to compromise Oracle Application Development Framework (ADF). Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Application Development Framework (ADF) accessible data. CVSS 3.1 Base Score 4.1 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:N/A:N).
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Compensating control
Restrict interactive/logon access to the hosts where Oracle Application Development Framework (ADF) executes to a minimal set of trusted administrative accounts and trusted source IPs using network ACLs or firewall rules.
- Compensating control
Enforce least-privilege on accounts with the ability to log on to ADF infrastructure: remove unnecessary administrative privileges and restrict which accounts may perform local/remote administrative logons (SSH/RDP).
- Compensating control
Isolate ADF runtime and management interfaces from general-purpose networks (network segmentation) so only required management/workstation networks can reach the ADF hosts.
- Operational
Enable and review logging and audit of privileged logons to the infrastructure hosting ADF; implement alerting for anomalous or unauthorized privileged logons and investigate any suspicious activity.
Event History
Frequently Asked Questions
What is the severity of CVE-2026-46771?
The severity of CVE-2026-46771 is medium, rated at 4.1.
How do I fix CVE-2026-46771?
To fix CVE-2026-46771, update to a supported version of Oracle Application Development Framework that is not affected by the vulnerability.
What components are affected by CVE-2026-46771?
CVE-2026-46771 affects the Java Business Objects component of the Oracle Application Development Framework in Oracle Fusion Middleware.
Who is at risk from CVE-2026-46771?
High privileged attackers with logon credentials are at risk of exploiting CVE-2026-46771.
What versions of Oracle ADF are impacted by CVE-2026-46771?
The affected versions of Oracle Application Development Framework are 12.2.1.4.0 and 14.1.2.0.0.